CVE-2025-7401

CRITICAL

WordPress Premium Age Verification <3.0.2 - Info Disclosure

Title source: llm

Description

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

Exploits (2)

github WORKING POC 2 stars
by Nxploited · pythonpoc
https://github.com/Nxploited/CVE-2025-7401
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-7401

Scores

CVSS v3 9.8
EPSS 0.0095
EPSS Percentile 76.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
aa-team/Premium Age Verification / Restriction for WordPress < 3.0.2
Published Jul 11, 2025
Tracked Since Feb 18, 2026